New Worm Searches Google For Victims

CYBERSPACE — A new Internet worm discovered today uses popular search engine Google to find potential victims and has caused what antivirus firm Kaspersky calls an “epidemic.”

Net-Worm.Perl.Santy.a, which targets the phpBB online bulletin board software, apparently searches Google for “viewfiles.php” which reveals vulnerable versions of phpBB, then launches an attack on the site.

“Santy.a is something of a novelty,” Kaspersky said. “It creates a specially formulated Google search request which results in a list of sites running vulnerable versions of phpBB.”

Once the virus has located its targets and successfully infected a site, it searches for and overwrites files with .asp, .htm, .jsp, .php, .phtm, and .shtm extensions. In their place, the worm places files which contain the text, “This site is defaced!!! NeverEverNoSanity WebWorm generation.”

Original reports suggested that the worm was exploiting one of the major PHP vulnerabilities announced last week by the open-source group that distributes the programming language, but the Internet Storm Center recently stated that the exploit lies in the “highlight” feature in versions of phpBB earlier than 2.0.11.

The “highlight” exploit centers around an SQL injection bug that allows attackers to arbitrarily execute code.

A search using Microsoft’s search engine for text strings contained in infected files turned up approximately 40,000 sites at 11 a.m. on Tuesday. The same search conducted at 12:30 p.m. revealed 133,780 hits.

“Santy.a is spreading rapidly and has caused an epidemic,” Kaspersky stated. “However, this does not directly affect users. Although the worm infects websites, it does not infect computers used to view those sites.”

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Adult Trade Group Pearl Industry Network to Debut at Taboo Vancouver

Pearl Industry Network (PiN), a new trade group for the adult industry focused on content creators, will debut at Taboo Vancouver adult lifestyle and wellness expo next week.

New Creator Platform 'OnlyPhones' Launches

OnlyPhones, a new phone-based creator platform, has officially launched.

AEBN Reveals Ariel Demure as Top Trans Star for Q4 of 2025

AEBN has published its top trans stars list for the fourth quarter of 2025, with reigning XMAs Trans Performer of the Year Ariel Demure landing atop the leaderboard.

Rebel Lynn Launches 'PoleVixens' Through Paysite.com

Rebel Lynn has launched her new pole dancing-themed membership site, PoleVixens, through Paysite.com.

Pineapple Support Taps Athena Bellamy as Brand Ambassador

Pineapple Support has named Athena Bellamy as its newest brand ambassador.

AV Bulletin: Health Warnings, VPNs and Exemptions

Since the Supreme Court’s decision in Free Speech Coalition v. Paxton, more state age verification laws have been introduced around the United States, as well as at the federal level and in other countries. This roundup provides an update on the latest news and developments on the age verification front as it impacts the adult industry.

Blake Blossom, Derek Kage Cap AEBN's Top Stars for 4th Quarter of 2025

AEBN has revealed its most popular performers in straight and gay theaters for the fourth quarter of 2025.

Adult Time Renews Silver Sponsorship for Pineapple Support

Adult Time has renewed its sponsorship of Pineapple Support at the Silver level.

Pornhub to Block UK Users Without Accounts Starting Feb. 2

Pornhub parent company Aylo will block access to its free video-sharing platforms in the United Kingdom starting Feb. 2 unless users have already set up accounts prior to that date, the company announced Tuesday.

Aylo Wins Another Major Piracy Lawsuit

For the second time in recent weeks, Pornhub parent company Aylo has prevailed in a copyright infringement case against sites pirating its content.

Show More